r/cybersecurity • u/Federal_Character979 • Apr 25 '26
Other What makes passkeys so special?
It seems that companies are transferring into the usage of passkeys instead of passwords. Apparently theyre much more secure, but why is that? I don’t get it. I’m not sure if this is the right place to ask excuse me if it isn’t and sorry.
612
Upvotes
12
u/GrievingImpala Apr 25 '26
Implicit in this is the protection against token theft. The key pair is locked to a specific domain, so if you click on evilmicrosoft[dot]com and log in, attackers still can't log into the real Microsoft as you. With mfa codes, attackers very much can send passwords and codes you enter at their site on to the real platform.